The Gentlemen is a ransomware-as-a-service operation that emerged in mid-2025 and rapidly became one of the most active ransomware groups in 2026. Reporting indicates the group grew out of personnel previously associated with Qilin before operating independently. Internal leak material exposed a compact core team of roughly nine operators supported by a broader affiliate base, consistent with a RaaS model in which most intrusions were conducted by partners and revenue was shared with affiliates. The group conducts financially motivated double-extortion operations, combining data theft with system encryption and public leak-site pressure. Its activity has been especially prominent in South America, where it has been identified as the leading ransomware actor in that sub-region, while also maintaining substantial activity in North America and additional victims across Europe, Asia, and Oceania. Confirmed victim geography includes the United States, Brazil, Australia, Switzerland, Italy, Malaysia, and Japan among many others. Observed victim sectors include retail, healthcare, professional services, hospitality, environmental services, and organizations assessed as operationally sensitive or business-critical. The Gentlemen’s intrusion tradecraft relies primarily on established access paths rather than novel exploitation. Reported initial access methods include scanning for exposed SSL VPN infrastructure, brute-force activity, and acquisition or abuse of stolen credentials from access brokers. Leaked internal discussions also indicate deliberate target selection using external business intelligence to assess industry, revenue, geography, and likely pressure to pay. Once inside a network, the group has been observed performing internal reconnaissance, abusing Active Directory for privilege escalation and domain control, moving laterally across systems, disabling or evading endpoint defenses, locating and disrupting backups, exfiltrating data, and then deploying ransomware. The leaked operational material further showed that the group regarded initial access and lateral movement as more challenging than the final encryption phase, and that it actively shared techniques for reconnaissance, defense evasion, and backup interference. The same material indicated use of AI coding assistants to accelerate development of its ransomware management panel, reportedly reducing build time to only a few days. This reflects operational efficiency rather than novel capability, but it underscores the group’s ability to scale quickly. Known aliases include gentleman, gentlemen, gentleman_group, gentlemen_ransomware_group, gentlemen_raas_affiliates, Storm-2697, the_gentleman, and the_gentlemen.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2024-55591 (Fortinet's FortiOS and FortiProxy)
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-33073 (Windows SMB Client)
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-32433 (Erlang/OTP SSH server)
Privilege Escalation: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-7771 ( ThrottleStop.sys driver)
NetLogon CVE-2020-1472 ("ZeroLogon") TheGentlemen
5 more CVEs tied to this actor tracked in Mallory.
256 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A rapidly growing ransomware group whose leaked internal chats revealed a small core team, affiliate-driven operations, high revenue sharing, AI-assisted platform development, and reliance on exposed VPN scanning, brute force, and purchased stolen credentials for initial access.
Emerging ransomware operator and the dominant South America-focused threat actor in the dataset, with notable activity against manufacturing, construction, healthcare, and IT services.
Rapidly growing ransomware operator and the dominant named threat in South America, while also maintaining notable activity in North America.
Named as the ransomware group responsible for an attack against IPS, an Italian organization.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.